CVE-2025-58375

Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.
Configurations

No configuration.

History

No history.

Information

Published : 2025-09-06 00:15

Updated : 2026-09-08 20:51


NVD link : CVE-2025-58375

Mitre link : CVE-2025-58375

CVE.ORG link : CVE-2025-58375


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')